Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown
CVE-2012-6645
Disclosure Date: April 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of a node, a different vulnerability than CVE-2012-1561.
0
Attacker Value
Unknown
CVE-2012-1561
Disclosure Date: April 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities."
0
Attacker Value
Unknown
CVE-2012-6065
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
The OM Maximenu module 6.x-1.43 and earlier for Drupal, when the "Title has PHP" option is enabled, allows remote authenticated users with the "Administer OM Maximenu" permission to execute arbitrary PHP code via a "Link Title," a different vulnerability than CVE-2012-5553.
0
Attacker Value
Unknown
CVE-2012-5553
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal allow remote authenticated users with the "administer OM Maximenu" permission to inject arbitrary web script or HTML via the (1) Menu Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary names.
0
Attacker Value
Unknown
CVE-2012-1649
Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1648
Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1641
Disclosure Date: August 28, 2012 (last updated October 05, 2023)
The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via admin/build/finder/import.
0
Attacker Value
Unknown
CVE-2010-4864
Disclosure Date: October 05, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.
0
Attacker Value
Unknown
CVE-2010-2857
Disclosure Date: July 25, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.
0
Attacker Value
Unknown
CVE-2010-2350
Disclosure Date: June 21, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the PNG decoder in Ziproxy 3.1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNG file.
0